Pascal Steichen, CEO of the Luxembourg House of Cybersecurity (LHC), and Dominique Kogue, Director of the National Centre of Competence in Cybersecurity (NC3). (Photo: Paperjam)

Pascal Steichen, CEO of the Luxembourg House of Cybersecurity (LHC), and Dominique Kogue, Director of the National Centre of Competence in Cybersecurity (NC3). (Photo: Paperjam)

Strengthening the resilience of the economy involves the cybersecurity of SMEs. By mobilising the national ecosystem and supporting businesses in their efforts, the Luxembourg House of Cybersecurity is helping to build a more secure, sustainable and innovative digital environment.

The way in which cybersecurity is approached has changed considerably in recent years. It is no longer just a question of putting in place protective measures: companies must now develop their ability to deal with any incident.

“With this in mind, companies need to adopt a proactive approach,” comments the CEO of the Luxembourg House of Cybersecurity (LHC), Pascal SteichenPascal Steichen. “More than ever, everyone needs to be aware of the risks to which they are exposed, following an attack or when a service provider fails. That way, we can take preventive measures, prepare ourselves and limit the damage associated with an incident.”

Assessing your level of maturity

With a view to supporting businesses, and in particular SMEs, in the face of cyber threats and risks, the Luxembourg government has taken a series of initiatives.

Firstly, the LHC is offering economic players the opportunity to benefit from an assessment of their level of maturity in the field of cybersecurity. “We intervene free of charge with the various players to assess their posture in this area, establish a set of observations and recommend the implementation of measures and controls enabling them to raise their level of maturity,” explains the director of the National Cyber Security Competence Centre (NC3), Dominique KogueDominique Kogue.

In Luxembourg, there are many service providers who can help companies with this process. “Our vocation, as a public institution under the Ministry of the Economy, is not to replace these players, but to support the strengthening of the overall ecosystem. In this respect, our ambition is to engage SMEs in a security improvement process and to put them in touch with the service providers best placed to support them over the long term,” says Pascal Steichen.

Lifting the budgetary hurdle

Beyond the initial assessment, the State provides financial assistance through SME Packages – Cybersecurity to companies wishing to implement the recommended measures.

This aid covers 70% of the costs associated with their steps, for an intervention of between 3,000 and 25,000 euros maximum. “These measures are now essential to help businesses meet the challenge of cybersecurity,” says Dominique Kogue. “Firstly, because SMEs make up more than 90% of Luxembourg's economic fabric. On the other hand, because the regulations around the issues of service continuity and resilience are becoming stricter, particularly with the expected transposition of NIS2 in Luxembourg.”

Anticipating regulatory changes

The evolution of the directive on the cybersecurity of essential services (NIS) considerably broadens the scope of the entities concerned. “While not all SMEs fall within the scope of NIS2, many are affected indirectly, as suppliers of services to the players now required to meet these obligations. If they want to continue to support these players, they need to raise their level of maturity,” continues the CEO of the LHC. “By raising players' awareness of these issues, the aim is to support a more resilient economy.”

Increasing employee awareness

Enhancing your level of cybersecurity maturity, beyond awareness of the issues and risks, involves putting in place measures to protect and monitor IT environments, but also - and above all - raising awareness among employees throughout the company.

“It is important to train everyone and make them aware of the risks, as attackers often seek to exploit human vulnerabilities,” explains Dominique Kogue. “In this respect, without necessarily going as far as implementing complex procedures, we can share good practice and raise awareness around digital hygiene measures: inviting people to choose sophisticated passwords, to change default credentials with personalised identifiers that comply with good security practice, to use protected channels for exchanging documents containing confidential data... That already goes a long way.”

IA and quantum computing: Anticipating future challenges

Adopting a proactive approach to cybersecurity, over and above supporting SMEs, also involves anticipating future challenges, linked in particular to the emergence of new technologies, such as artificial intelligence or quantum computing.

“These developments are overturning the traditional approach to security. With AI, for example, new risks are emerging, linked to the manipulation of algorithms or data, which can lead to altered decision-making, biases or hallucinations. Furthermore, correcting a vulnerability detected in an AI model is not as easy as for software. This should prompt us to rethink our cybersecurity approaches,” comments Pascal Steichen.

Innovate and co-create to stay at the cutting edge

In this context, a new initiative supported by the LHC has come into being: the Cybersecurity Factory. “This is part of the government's Data, AI and Quantum strategy, of which it is a component alongside, for example, the AI Factory,” continues the CEO of the LHC. “In view of the changing risks and forms of attack, the intention is to invite players in the cybersecurity ecosystem to explore new approaches and co-create innovative tools, drawing on dedicated resources.”

In this way, the Luxembourg cybersecurity ecosystem intends to remain at the cutting edge and respond effectively to the challenges of tomorrow.